Нпо Ритм · Georitm · CVE-2026-100903
**Name of the Vulnerable Software and Affected Versions**
ООО НПО Ритм GEOritm versions prior to 2.46
**Description**
A flaw in the REST API component allows remote attackers to bypass authentication. By manipulating the `objectId` argument within the '/restapi/objects/obj-groups' endpoint, an unauthorized user can gain access to the system.
**Recommendations**
Update to version 2.46.